Last updated: 26 August 2026
FillMyShift ("we", "us", "our") provides software that helps UK homecare and domiciliary care providers ("Customers", "you") find and offer shifts to their carers. This policy explains how we collect, use, and protect personal data when you use our website and platform at care-quickfill.lovable.app (and any successor domain) (the "Service").
We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
FillMyShift is operated by FillMy Shift, a business based in Coventry, United Kingdom. You can contact us at hello@cm16digital.com.
For most of the personal data described below, FillMyShift acts as a data processor on behalf of our Customers (the care organisations who use our platform), who act as the data controller. Where we collect data directly for our own purposes (for example, to run our business, market our Service, or manage billing), we act as the data controller. See our Data Processing Agreement for details on our processor relationship with Customers.
2. What data we collect
2.1 Data about coordinators and organisation users
When a care organisation signs up, we collect:
- Full name, work email address, job role
- Organisation name and postcode
- Password (stored securely, hashed — we never store this in plain text)
- Billing details (handled directly by our payment processor, Stripe — see section 6)
2.2 Data about carers
Care organisations use our platform to manage their own carers' details. This typically includes:
- Full name and phone number
- Availability, skills, and reliability information entered by the organisation
- Shift offer history (offers sent, viewed, accepted, or declined)
- If push notifications are enabled: a device push subscription token (this does not identify the carer's device owner directly to us, only enables message delivery)
We collect and process this carer data on behalf of and under the instruction of the care organisation that added it — we do not independently decide how this data is used. If you are a carer and have questions about your data, please contact the care organisation that added you to the platform in the first instance; you can also contact us directly and we will assist or direct your request appropriately.
2.3 Automatically collected data
When you visit our website or use the Service, we may automatically collect:
- IP address, browser type, device type
- Pages visited, time spent, general usage patterns (via standard analytics tools)
- Cookies necessary for the Service to function (e.g. keeping you logged in)
We do not use advertising cookies or sell any data to third-party advertisers.
3. How we use data
We use personal data to:
- Provide and operate the Service (creating accounts, matching carers to shifts, sending shift offers)
- Send shift offer notifications via push notification or SMS
- Process payments and manage subscriptions
- Respond to support requests and demo bookings
- Monitor, maintain, and improve the Service (including fixing bugs and understanding usage patterns)
- Meet legal and regulatory obligations
- With consent or legitimate interest, send product updates or marketing communications (you can unsubscribe at any time)
4. Legal basis for processing
Depending on the data and purpose, we rely on:
- Contract — to provide the Service you or your organisation has signed up for
- Legitimate interests — to improve the Service, prevent fraud, and maintain security
- Consent — for optional communications and for enabling push notifications on a carer's device
- Legal obligation — for tax, accounting, and regulatory compliance
5. Sharing your data
We do not sell personal data. We share data with:
- Stripe (payment processing) — to handle subscription billing. See Stripe's own privacy policy for how they process payment data.
- Our push notification and SMS providers — solely to deliver shift offer notifications to carers.
- Cloud hosting and database providers (e.g. Supabase, and our hosting platform) — to store and run the Service securely.
- Law enforcement or regulators, where legally required.
All third-party processors we use are contractually bound to protect personal data in line with UK GDPR requirements.
6. Payment data
Subscription payments are processed entirely by Stripe. We do not store your full card details on our own servers. Stripe's handling of your payment data is governed by Stripe's own privacy policy, available at stripe.com/privacy.
7. International data transfers
Some of our service providers may process data outside the UK/EEA. Where this happens, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent protections recognised under UK GDPR.
8. Data retention
We retain personal data for as long as necessary to provide the Service and comply with legal obligations. Specifically:
- Coordinator/organisation account data is retained for the life of the subscription and for a reasonable period afterward for legal, tax, and dispute-resolution purposes.
- Carer data is retained according to the instructions of the care organisation that added it, and is deleted or returned to the organisation on request or on termination of their subscription, in line with our Data Processing Agreement.
- Billing records are retained as required by UK tax law (typically 6 years).
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data (subject to legal retention requirements)
- Object to or restrict certain processing
- Request data portability
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk
If you are a carer whose data was added by a care organisation, please contact that organisation first, as they control how your data is used — we will support and forward relevant requests to them where appropriate.
To exercise any of these rights, contact us at hello@cm16digital.com.
10. Security
We use industry-standard technical and organisational measures to protect personal data, including encrypted data storage, access controls, and secure authentication. No system is completely secure, and we continually review and improve our practices.
11. Children's data
The Service is not directed at or intended for use by children, and we do not knowingly collect data from anyone under 18.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify Customers of material changes via email or an in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
Email: hello@cm16digital.com
Based in: Coventry, United Kingdom